TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How I got a $3,500 USD Facebook Bug Bounty

145 pointsby fransrover 12 years ago

9 comments

shimon_eover 12 years ago
I submitted a report to facebook about privacy setting circumvention. Didn't receive a response. Didn't receive a bounty. Facebook DID fix the bug after some months.<p>Feel a bit cheated that a billion dollar company couldn't take the time to respond... if I had the time I'd follow up with them.
评论 #4986959 未加载
评论 #4986391 未加载
评论 #4985949 未加载
评论 #4989776 未加载
评论 #4985755 未加载
评论 #4985831 未加载
killahpriestover 12 years ago
Whenever people teaching others about security mention XSS, I've always wondered does it really even happen in the real world? I'm sure everybody escapes their input.<p>Turns out there's a reason XSS is so often mentioned. Even Dropbox and Facebook fell prey to it (although in this case the input wasn't from the web, but rather from their desktop application/service partner).
评论 #4987843 未加载
评论 #4985775 未加载
评论 #4986153 未加载
评论 #4985718 未加载
评论 #4988440 未加载
评论 #4986075 未加载
gklittover 12 years ago
Props to Facebook for being so responsible about fixing this bug. After seeing so many blog posts about companies not responding to emails from whitehats finding XSS vulnerabilities (<a href="http://www.troyhunt.com/2012/08/why-xss-is-serious-business-and-why.html" rel="nofollow">http://www.troyhunt.com/2012/08/why-xss-is-serious-business-...</a>), it's comforting to see someone take such reports seriously.
评论 #4989944 未加载
tommiover 12 years ago
I bet Blackhat Vulnerability Program would've payed lot more.
评论 #4986081 未加载
评论 #4985636 未加载
评论 #4989791 未加载
评论 #4986087 未加载
评论 #4986060 未加载
jbverschoorover 12 years ago
lol.. I found a bug in paypal which allowed me to transfer funds from one account to another, even though this was prohibited.<p>I got nothing. Maybe next time I'll just post this stuff for random people on twitter to find
评论 #4988215 未加载
tomjen3over 12 years ago
Wauw, so all that happens if you save dropboxs ass is that you get a special mention on their special page that very few people know about?<p>Why even bother to tell them then?
评论 #4987754 未加载
评论 #4987844 未加载
评论 #4988935 未加载
评论 #4988476 未加载
评论 #4986802 未加载
评论 #4988936 未加载
tokipinover 12 years ago
wait facebook has like millions of bugs -.- though maybe UI glitches aren't considered bugs
wilfraover 12 years ago
I submitted an error (and a solution) in their open graph docs that caused a bug if anybody copy/pasted the code from their site. The error was fixed within hours, however I never got any money or even an email :(
评论 #4986113 未加载
评论 #4985829 未加载
robmcveyover 12 years ago
BAM!